home.social

#cve202642945 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve202642945, aggregated by home.social.

  1. I don't wanna ruin your Friday, but nginx has a serious CVE with a rating of 9.2, and you should patch or mitigate it asap.

    The CVE is an unauthenticated http request that can lead to a deterministic buffer overflow and remote code execution.

    depthfirst.com/nginx-rift

    #nginx #cve_2026_42945 #cve202642945

  2. I don't wanna ruin your Friday, but nginx has a serious CVE with a rating of 9.2, and you should patch or mitigate it asap.

    The CVE is an unauthenticated http request that can lead to a deterministic buffer overflow and remote code execution.

    depthfirst.com/nginx-rift

    #nginx #cve_2026_42945 #cve202642945

  3. I don't wanna ruin your Friday, but nginx has a serious CVE with a rating of 9.2, and you should patch or mitigate it asap.

    The CVE is an unauthenticated http request that can lead to a deterministic buffer overflow and remote code execution.

    depthfirst.com/nginx-rift

    #nginx #cve_2026_42945 #cve202642945

  4. I don't wanna ruin your Friday, but nginx has a serious CVE with a rating of 9.2, and you should patch or mitigate it asap.

    The CVE is an unauthenticated http request that can lead to a deterministic buffer overflow and remote code execution.

    depthfirst.com/nginx-rift

    #nginx #cve_2026_42945 #cve202642945

  5. ⚠️ NGINX `rewrite` vulnerability

    Using unnamed regex captures (`$1`, `$2`) with `?` in replacement strings plus `rewrite`/`if`/`set` can be triggered **without auth**.

    Systems with ASLR disabled are at risk of remote code execution. Patch immediately!

    my.f5.com/manage/s/article/K00

    nvd.nist.gov/vuln/detail/CVE-2

    #NGINX #CVE202642945 #ZeroDay #InfoSec #RCE #CyberSecurity

  6. ⚠️ NGINX `rewrite` vulnerability

    Using unnamed regex captures (`$1`, `$2`) with `?` in replacement strings plus `rewrite`/`if`/`set` can be triggered **without auth**.

    Systems with ASLR disabled are at risk of remote code execution. Patch immediately!

    my.f5.com/manage/s/article/K00

    nvd.nist.gov/vuln/detail/CVE-2

    #NGINX #CVE202642945 #ZeroDay #InfoSec #RCE #CyberSecurity

  7. ⚠️ NGINX `rewrite` vulnerability

    Using unnamed regex captures (`$1`, `$2`) with `?` in replacement strings plus `rewrite`/`if`/`set` can be triggered **without auth**.

    Systems with ASLR disabled are at risk of remote code execution. Patch immediately!

    my.f5.com/manage/s/article/K00

    nvd.nist.gov/vuln/detail/CVE-2

    #NGINX #CVE202642945 #ZeroDay #InfoSec #RCE #CyberSecurity

  8. ⚠️ NGINX `rewrite` vulnerability

    Using unnamed regex captures (`$1`, `$2`) with `?` in replacement strings plus `rewrite`/`if`/`set` can be triggered **without auth**.

    Systems with ASLR disabled are at risk of remote code execution. Patch immediately!

    my.f5.com/manage/s/article/K00

    nvd.nist.gov/vuln/detail/CVE-2

    #NGINX #CVE202642945 #ZeroDay #InfoSec #RCE #CyberSecurity

  9. ⚠️ NGINX `rewrite` vulnerability

    Using unnamed regex captures (`$1`, `$2`) with `?` in replacement strings plus `rewrite`/`if`/`set` can be triggered **without auth**.

    Systems with ASLR disabled are at risk of remote code execution. Patch immediately!

    my.f5.com/manage/s/article/K00

    nvd.nist.gov/vuln/detail/CVE-2

    #NGINX #CVE202642945 #ZeroDay #InfoSec #RCE #CyberSecurity

  10. NGINX Vulnerability Exposes Servers to DoS, Potential Code Execution

    A critical vulnerability, CVE-2026-42945, has been lurking in NGINX's code for 18 years, exposing servers to potential DoS attacks and code execution - and affecting a staggering third of the top-ranked websites. This heap buffer overflow flaw, rated 9.2 in severity, is a wake-up call for NGINX users to take immediate action.

    osintsights.com/nginx-vulnerab

    #Cve202642945 #Nginx #WebServer #HeapBufferOverflow #DenialOfService

  11. NGINX Flaw Enables Unauthenticated Remote Code Execution

    A critical 18-year-old vulnerability, known as NGINX Rift, has been discovered in NGINX Plus and NGINX Open Source, allowing unauthenticated attackers to remotely execute code with a single crafted HTTP request. This high-severity flaw, rated 9.2 on the CVSS v4 scale, poses a significant threat to vulnerable servers.

    osintsights.com/nginx-flaw-ena

    #Nginx #RemoteCodeExecution #Cve202642945 #UnauthenticatedAttacks #HeapBufferOverflow